us

216.73.216.144

Back
News

AMLA Flags Crypto AML Risks as MiCAR Deadline Passes

AMLA Flags Crypto AML Risks as MiCAR Deadline Passes
Amir Rizwan Amir Rizwan JULY 2, 2026 1 minute read

The EU’s Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) published an advisory note on 29 June 2026 warning that the end of the MiCAR transitional period is creating new money laundering and terrorist financing risks across the bloc’s crypto-asset sector. The transitional arrangement expired on 1 July 2026, and from that date only firms authorised under the Markets in Crypto-Assets Regulation (MiCAR) as crypto-asset service providers, or CASPs, may legally operate in the EU.

The grandfathering arrangement stems from Article 143(3) of Regulation (EU) 2023/1114, according to AMLA’s advisory note, and had allowed crypto-asset service providers operating under applicable national law before 30 December 2024 to keep trading while they sought authorisation. Unauthorised virtual asset service providers, or VASPs, must now wind down or cease EU operations, while their customers migrate to a smaller pool of authorised CASPs. AMLA’s note sets out risks and mitigation measures across four groups: unauthorised VASPs exiting the market, authorised CASPs absorbing new customers, AML/CFT supervisors overseeing the transition, and financial intelligence units tracking the resulting fund flows.

For authorised CASPs, AMLA warns that onboarding customers from unauthorised VASPs can produce materially different risk profiles, including a concentration of higher-risk customers among the CASPs that remain in the market. The note adds that rapid customer inflows may strain transaction monitoring systems and compliance resources, requiring firms to adjust staffing and system capacity to keep managing ML/TF risk effectively as volumes rise.

AMLA describes the broader market reconfiguration as having a material impact on the functioning of the EU crypto-asset ecosystem, pointing to compressed wind-down timelines, concentration of activity among fewer authorised CASPs, and reduced transparency during exits as conditions that could be exploited to conceal illicit fund movements or evade sanctions. The note also flags new supervisory blind spots, since customer transfers and risk migration are happening simultaneously across jurisdictions with differing national wind-down frameworks, along with new typologies that financial intelligence units may need to track as asset bases move across multiple CASPs.

AMLA’s advisory is explicit that customers migrating from unauthorised VASPs should not face blanket de-risking, but instead individual risk assessments under a risk-based approach, with enhanced due diligence applied only where warranted. That guidance points to a structural strain: CASPs absorbing large volumes of new customers within a compressed timeframe need onboarding and transaction-monitoring systems that can scale quickly, without either defaulting to wholesale rejections or missing the elevated-risk profiles the note warns about.

Meeting that standard requires identity verification and AML screening infrastructure built to absorb volume spikes without slowing onboarding or resorting to blanket refusals. Shufti’s AML screening checks incoming customers against global sanctions, PEP, and adverse media watchlists, while its KYC and crypto solutions cover onboarding across 240+ countries and territories, supporting the kind of individual, risk-based assessment AMLA’s note calls for. CASPs adjusting their compliance stack as the EU crypto market consolidates can request a demo to see how the platform handles onboarding at scale.

Disclaimer: The views and opinions expressed on this webpage or weblink are those of the author only, and are not necessarily the views or opinions of Shufti Pro Limited. The material and information on this weblink is solely for general information purposes. You should not rely upon the material or information on the website as a basis for making any business or legal decision.

While we endeavor to keep the information up-to-date and/or correct, we make no representations or warranties of any kind, express or implied, or for any purpose about the completeness, accuracy, reliability, suitability, or availability of the contents or information herein. Any reliance on its content is thus entirely at your own risk.

For the avoidance of doubt, Shufti Pro Limited will not be liable for any false, inaccurate, inappropriate, or incomplete information presented herein, and all liabilities with respect to actions taken, or not taken, based on the contents or information herein, or for any loss sustained by you as a consequence are hereby expressly disclaimed by us.

Share you link

Bring your voice

Bring Your Voice.

The community for every hand that writes and every voice that speaks against fraud.

Join Community

Pitch a piece and get a verified byline in the Media room.

“Industry Partnerships That Create Real Value”

Join Shufti’s partnership network to expand your connections, collaborate with industry leaders, and unlock new opportunities.

Pitch a piece and get a verified byline in the Media room.

Partnership Inquiries?
Email us at [email protected]

iBeta Level 1 — ISO 30107-3 Compliant iBeta Level 2 — ISO 30107-3 Compliant iBeta Level 3 — ISO 30107-3 Compliant PCI DSS SOC 2 Type 2 GDPR GDPR Fundamentals — Quality Guild ISO 27001:2022 KJM Age Verification CCPA / CPRA Cyber Essentials Cyber Essentials Plus
Copyright © 2026 Shufti. All rights reserved.